Flattr button causing XSS & clickjacking warnings

Ask for help about NoScript, no registration needed to post
sigdrifa

Flattr button causing XSS & clickjacking warnings

Post by sigdrifa »

I just signed up for flattr.com and noticed two problems:

First, I installed the Flattr plugin on my blog ( http://www.lazyteddy.com ), and now I get an XSS warning every time I load the page.

Second, when I clicked on the Flattr button on another website (in this case http://www.taz.de ) I got a clickjacking warning.

Now, the second problem is nothing I can do anything about except carefully checking the message and then allow on a case-by-case basis. But I would like to know if there's anything I can do on my blog to make sure my readers don't get the XSS warning — obviously that's not something that's good for my reputation :(

Suggestions, anyone?

Thanks
Sigdrifa
Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8 GTB7.1
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: Flattr button causing XSS & clickjacking warnings

Post by Alan Baxter »

sigdrifa wrote:I installed the Flattr plugin on my blog ( http://www.lazyteddy.com ), and now I get an XSS warning every time I load the page.
Confirmed using NoScript 2.0.1rc2.
Default settings except Allowed lazyteddy.com, flattr.com
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
sigdrifa

Re: Flattr button causing XSS & clickjacking warnings

Post by sigdrifa »

I've replaced the Wordpress plugin with a single button for now; that's working fine, although not quite what I wanted because it only flattrs the entire site, not a single article.

It appears that the problem with the plugin has something to do with the iframe that's being placed on the site for every Flattr button. I suppose it's more likely that it's a problem on the Flattr end and not with NoScript.

Still, if anyone else comes across the problem and has a solution, I'd still be interested.
Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8 GTB7.1
Post Reply